33% of ISO 27019 you already have
SSAE 18 already covers about 33% of ISO 27019, leaving
31 of 46 controls as genuinely new work.
Already covered 7
Likely covered 8
New work 31
What is genuinely new work
Nothing in SSAE 18 reaches these. This is the list to scope.
ISO27019-01Critical asset identification and inventory
ISO27019-03Security governance structure
ISO27019-04Roles and responsibilities for critical systems
ISO27019-05Security policy for operational technology
ISO27019-06Physical and logical access controls
ISO27019-09Interactive remote access security
ISO27019-11.1.1Physical Security for Substations and Plants
ISO27019-11.2.4Maintenance of Process Control Equipment
ISO27019-12.1.2Change Management for Control Systems
ISO27019-12.2.1Malware Protection in OT
ISO27019-12.3.1Backup of Control System Configurations
ISO27019-12.4.1Event Logging in Control Systems
ISO27019-12.6.1Vulnerability Management for OT
ISO27019-13.1.1Network Security for Energy Operations
ISO27019-13.1.3Segregation of Networks
ISO27019-14.2.1Secure Development of Control Applications
ISO27019-15Ports and services management
ISO27019-15.1.1Supplier Relationships in Energy
ISO27019-16.1.1Incident Management for Energy Operations
ISO27019-17Recovery plan for critical systems
ISO27019-17.1.2Business Continuity for Energy Supply
ISO27019-18.1.1Compliance with Energy Sector Regulations
ISO27019-19Coordination with sector-specific agencies
ISO27019-6.1.1Information Security Roles for Energy Operations
ISO27019-6.1.5Information Security in Project Management for Energy
ISO27019-7.1.1Screening of Personnel with OT Access
ISO27019-8.1.1Inventory of Process Control Assets
ISO27019-8.2.1Classification of Energy Sector Information
ISO27019-9.1.1Access Control Policy for Control Systems
ISO27019-9.2.3Privileged Access in Control Environments
ISO27019-ENR.1Safety and Security Integration
Show the 15 you already have
ISO27019-07Personnel risk assessment
ISO27019-16Incident response plan for operational disruptions
ISO27019-18Reporting obligations to authorities
ISO27019-20Exercises and drills for OT incidents
ISO27019-21Supply chain risk management for critical components
ISO27019-23Change management procedures
ISO27019-24Vulnerability assessment for critical systems
ISO27019-02System security categorization
ISO27019-08Electronic access perimeter management
ISO27019-10Revocation of access procedures
ISO27019-11Security patch management for OT
ISO27019-12Malware prevention for operational systems
ISO27019-13Network security monitoring
ISO27019-14System security hardening
ISO27019-22Configuration management for OT systems
How this is calculated
Already covered means a mapping runs from a control in SSAE 18 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition